StudyToCert

All certifications / CCSP / Lessons

ISC2 Certified Cloud Security Professional 2026 outline (effective Aug 1, 2026) · Domain 1: Cloud concepts, architecture & design

Cloud reference architecture: IaaS, PaaS, SaaS service models and cloud service capabilities

▶ Watch the overview video

Last reviewed September 29, 2026 · Leer en español

A reference architecture is a shared map of the parts of a cloud service and who operates each one. The CCSP exam uses it to test whether you can tell what the customer controls in each service model, because that decides which security controls the customer must build and which it can only request or verify.

Infrastructure as a Service (IaaS) gives the customer virtual machines, virtual networks and storage. The provider runs the physical data center, hardware and hypervisor; the customer installs and patches the guest operating system, middleware and applications, and configures firewalls and identity. Platform as a Service (PaaS) moves the operating system and runtime to the provider: you deploy code or use a managed database, and the provider patches the platform underneath. Software as a Service (SaaS) delivers a finished application; the customer mainly controls its users, their permissions, configuration settings and the data it puts in.

ISO/IEC 17788 describes the same idea as cloud capability types. An infrastructure capability type lets the customer provision and use processing, storage or networking. A platform capability type lets the customer deploy and run applications written in languages and tools the provider supports. An application capability type lets the customer use the provider's applications. Named service categories such as compute as a service, data storage as a service, network as a service and communications as a service fit inside these types.

The pattern to remember is that as you move from IaaS to PaaS to SaaS, the customer gives up control and gains convenience. Less control means you rely more on contracts, service level agreements and third-party assurance reports to confirm the provider's controls. Some responsibilities never move: in every model the customer owns its data, decides who gets access, and is accountable to regulators and customers if that data is mishandled.

Key terms

IaaS
A service model in which the customer rents virtual compute, storage and networking and manages everything from the guest operating system up.
PaaS
A service model in which the provider runs the operating system and runtime, and the customer deploys and manages its own applications and data.
SaaS
A service model in which the provider delivers a complete application, and the customer manages users, configuration and data.
Cloud capability type
ISO/IEC 17788's classification of what a service offers the customer: infrastructure, platform or application capability.
Real-world example

A startup runs its web app on managed PaaS, keeps files in object storage and uses a SaaS email suite. When a critical kernel flaw is announced, the startup does nothing for the PaaS and SaaS parts because the providers patch those, but it must still patch the two IaaS virtual machines it runs for a legacy reporting tool.

Exam tip: When a question asks who patches the operating system, the answer depends on the model: the customer in IaaS, the provider in PaaS and SaaS. Data and access decisions stay with the customer in all three.

Check yourself

In PaaS, who is responsible for patching the runtime and operating system?

The provider; the customer is responsible for its application code, configuration and data.

Which service model gives the customer the most control and therefore the most security responsibility?

IaaS, because the customer manages the guest operating system and everything above it.

What does the application capability type describe?

A service where the customer uses the provider's applications, which corresponds to SaaS.

Study CCSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CCSP study plan